|
-
June 20th, 2002, 10:04 PM
#1
The Danger of Scrap Files
i went to this site http://www.mischel.dhs.org to download the latest version of
trojan hunter and came across this article http://www.mischel.dhs.org/scrapfiles.jsp
I'll quote just the intro and conclusion.
The Danger of Scrap Files
Magnus Mischel
Introduction
Many Internet users today know that they should never run executable or script files they receive via e-mail because of the danger of malicious code. So they set their Windows Explorer settings to show file extensions so they can recognize the dangerous file extensions like .exe, .vbs et. al. But what if there was a file type that could contain malicious code, and the file extension was automatically hidden from the user by Windows no matter what the Explorer settings? And what if that file had an icon that resembled a harmless text file? And what if double-clicking on such a file would execute the malicious code embedded in it?
Well, the bad news is that there does exist such a file type; it's called a Scrap File. The good news is that this article will teach you the basics about it, and how you can protect yourself
.
.
.
.
Conclusion
You should never double-click a scrap-file before you know what its contents are. This is a flaw in the OLE system that Microsoft should have corrected, given its implications in the security area. Even experienced computer users can be lured into running these files since they might assume that the file is harmless since it has no extension.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|